Linuxsecurity
Fedora Coturn 4.15.0 Security Advisory Addresses STUN Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Fedora released a security advisory for Coturn version 4.15.0, addressing critical vulnerabilities related to STUN attributes processing. The vulnerabilities allowed Coturn to incorrectly handle attributes following MESSAGE-INTEGRITY, potentially leading to interoperability issues. This advisory affects users of the Coturn TURN server, which is widely used for VoIP and NAT traversal. Key fixes include rejecting ACME requests properly and ensuring session resumes are bound to original allocation owners. The update is available for installation via the 'dnf' package manager. Users are urged to apply the update to mitigate potential risks. The advisory also highlights several other bug fixes related to message handling and buffer management.
Key Points: • Fedora's Coturn 4.15.0 addresses critical STUN attribute handling vulnerabilities. • The advisory includes fixes for interoperability issues and session management. • Users are advised to update their Coturn installations promptly to mitigate risks.